URL:

https://download-new.utorrent.com/endpoint/utweb/track/stable/os/win

Full analysis: https://app.any.run/tasks/74f3d5b3-28ed-4a6e-b377-49a8a1cb3c93
Verdict: Malicious activity
Threats:

Adware is a form of malware that targets users with unwanted advertisements, often disrupting their browsing experience. It typically infiltrates systems through software bundling, malicious websites, or deceptive downloads. Once installed, it may track user activity, collect sensitive data, and display intrusive ads, including pop-ups or banners. Some advanced adware variants can bypass security measures and establish persistence on devices, making removal challenging. Additionally, adware can create vulnerabilities that other malware can exploit, posing a significant risk to user privacy and system security.

Analysis date: December 23, 2019, 18:23:58
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
adware
pua
lavasoft
Indicators:
MD5:

E129E94B8A2BF23BC65E2E0E46D52BE7

SHA1:

2B4DEC0B74273F044BA3EC8A6EF44FC101346FD7

SHA256:

07B51B34BB81662FC6EB58C5B843A5A9F0C945F2974EB57B5E6881815B6B3BC3

SSDEEP:

3:N8SEmL3XeRLKeKLRSAsvONRXKKND:2SBeRLiL5sWNRXRND

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • utweb_installer.exe (PID: 2616)
      • utweb_installer.exe (PID: 4048)
      • installer.exe (PID: 2980)
      • GenericSetup.exe (PID: 3968)
    • Loads dropped or rewritten executable

      • GenericSetup.exe (PID: 3968)
    • LAVASOFT was detected

      • installer.exe (PID: 2980)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • chrome.exe (PID: 3668)
      • utweb_installer.exe (PID: 4048)
      • chrome.exe (PID: 3696)
    • Reads the Windows organization settings

      • GenericSetup.exe (PID: 3968)
    • Reads Environment values

      • GenericSetup.exe (PID: 3968)
    • Reads Windows owner or organization settings

      • GenericSetup.exe (PID: 3968)
    • Searches for installed software

      • GenericSetup.exe (PID: 3968)
  • INFO

    • Application launched itself

      • chrome.exe (PID: 3696)
    • Reads Internet Cache Settings

      • chrome.exe (PID: 3696)
    • Reads the hosts file

      • chrome.exe (PID: 3668)
      • chrome.exe (PID: 3696)
    • Reads settings of System Certificates

      • GenericSetup.exe (PID: 3968)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
52
Monitored processes
14
Malicious processes
5
Suspicious processes
0

Behavior graph

Click at the process to see the details
drop and start drop and start start drop and start chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs utweb_installer.exe no specs utweb_installer.exe #LAVASOFT installer.exe genericsetup.exe chrome.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1248"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1028,901776799176446446,6463511440258883314,131072 --enable-features=PasswordImport --lang=en-US --extension-process --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=5852819377304909212 --renderer-client-id=4 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=2312 /prefetch:1C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
75.0.3770.100
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
1724"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1028,901776799176446446,6463511440258883314,131072 --enable-features=PasswordImport --lang=en-US --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=16205737522539221651 --renderer-client-id=5 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=2232 /prefetch:1C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
75.0.3770.100
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
1908"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=watcher --main-thread-id=3336 --on-initialized-event-handle=312 --parent-handle=316 /prefetch:6C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
MEDIUM
Description:
Google Chrome
Exit code:
0
Version:
75.0.3770.100
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
2344"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Google\Chrome\User Data" /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Google\Chrome\User Data\Crashpad" "--metrics-dir=C:\Users\admin\AppData\Local\Google\Chrome\User Data" --url=https://clients2.google.com/cr/report --annotation=channel= --annotation=plat=Win32 --annotation=prod=Chrome --annotation=ver=75.0.3770.100 --initial-client-data=0x7c,0x80,0x84,0x78,0x88,0x712da9d0,0x712da9e0,0x712da9ecC:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
MEDIUM
Description:
Google Chrome
Exit code:
0
Version:
75.0.3770.100
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
2616"C:\Users\admin\Downloads\utweb_installer.exe" C:\Users\admin\Downloads\utweb_installer.exechrome.exe
User:
admin
Company:
BitTorrent, Inc.
Integrity Level:
MEDIUM
Description:
uTorrent Web
Exit code:
3221226540
Version:
1.0.6.1934
Modules
Images
c:\users\admin\downloads\utweb_installer.exe
c:\systemroot\system32\ntdll.dll
2704"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=gpu-process --field-trial-handle=1028,901776799176446446,6463511440258883314,131072 --enable-features=PasswordImport --gpu-preferences=KAAAAAAAAADgAAAgAQAAAAAAAAAAAGAAAAAAAAAAAAAIAAAAAAAAACgAAAAEAAAAIAAAAAAAAAAoAAAAAAAAADAAAAAAAAAAOAAAAAAAAAAQAAAAAAAAAAAAAAAFAAAAEAAAAAAAAAAAAAAABgAAABAAAAAAAAAAAQAAAAUAAAAQAAAAAAAAAAEAAAAGAAAA --service-request-channel-token=6966031053675814274 --mojo-platform-channel-handle=1036 --ignored=" --type=renderer " /prefetch:2C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
75.0.3770.100
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
2788"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --field-trial-handle=1028,901776799176446446,6463511440258883314,131072 --enable-features=PasswordImport --lang=en-US --no-sandbox --service-request-channel-token=1040995128588073090 --mojo-platform-channel-handle=1400 /prefetch:8C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
MEDIUM
Description:
Google Chrome
Exit code:
0
Version:
75.0.3770.100
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
2980.\installer.exeC:\Users\admin\AppData\Local\Temp\7zS0DF55119\installer.exe
utweb_installer.exe
User:
admin
Company:
adaware
Integrity Level:
HIGH
Description:
uTorrent Web
Exit code:
0
Version:
1.0.0.2289
Modules
Images
c:\users\admin\appdata\local\temp\7zs0df55119\installer.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3668"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --field-trial-handle=1028,901776799176446446,6463511440258883314,131072 --enable-features=PasswordImport --lang=en-US --service-sandbox-type=network --service-request-channel-token=5178664591445807881 --mojo-platform-channel-handle=1592 /prefetch:8C:\Program Files\Google\Chrome\Application\chrome.exe
chrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
MEDIUM
Description:
Google Chrome
Exit code:
0
Version:
75.0.3770.100
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
3692"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1028,901776799176446446,6463511440258883314,131072 --enable-features=PasswordImport --lang=en-US --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=9112090725101313947 --renderer-client-id=6 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=2212 /prefetch:1C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
75.0.3770.100
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
Total events
15 185
Read events
15 041
Write events
141
Delete events
3

Modification events

(PID) Process:(1908) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Chrome\BrowserExitCodes
Operation:writeName:3696-13221599053210125
Value:
259
(PID) Process:(3696) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon
Operation:writeName:failed_count
Value:
0
(PID) Process:(3696) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon
Operation:writeName:state
Value:
2
(PID) Process:(3696) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Chrome\ThirdParty
Operation:writeName:StatusCodes
Value:
(PID) Process:(3696) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Chrome\ThirdParty
Operation:writeName:StatusCodes
Value:
01000000
(PID) Process:(3696) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon
Operation:writeName:state
Value:
1
(PID) Process:(3696) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96}
Operation:writeName:dr
Value:
1
(PID) Process:(3696) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Chrome
Operation:writeName:UsageStatsInSample
Value:
0
(PID) Process:(3696) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Chrome\BrowserExitCodes
Operation:delete valueName:1512-13197841398593750
Value:
0
(PID) Process:(3696) chrome.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientStateMedium\{8A69D345-D564-463C-AFF1-A69D9E530F96}
Operation:writeName:usagestats
Value:
0
Executable files
16
Suspicious files
11
Text files
73
Unknown types
0

Dropped files

PID
Process
Filename
Type
3696chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\490d8ec1-a0a1-4cc3-95f6-331b18bff518.tmp
MD5:
SHA256:
3696chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\000020.dbtmp
MD5:
SHA256:
3696chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\CURRENT
MD5:
SHA256:
3696chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\CURRENT~RF38e1a5.TMP
MD5:
SHA256:
3696chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\shared_proto_db\LOG.old
MD5:
SHA256:
3696chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\LOG.oldtext
MD5:
SHA256:
3696chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Site Characteristics Database\LOG.old~RF38e118.TMPtext
MD5:
SHA256:
3696chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\ShaderCache\GPUCache\data_1
MD5:
SHA256:
3696chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Site Characteristics Database\LOG.oldtext
MD5:
SHA256:
3696chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\LOG.oldtext
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
10
TCP/UDP connections
14
DNS requests
10
Threats
1

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3968
GenericSetup.exe
GET
200
104.16.235.79:80
http://sos.adaware.com/v1/offer/detail/?_id=5fd07fc1850f5842e9fc04e2c09c91298edfbe34
US
html
454 Kb
whitelisted
3968
GenericSetup.exe
GET
200
104.16.235.79:80
http://sos.adaware.com/v1/offer/detail/?_id=94f71b6ccb0fa8bdc31a62d9ef805319995253be
US
html
50.0 Kb
whitelisted
3968
GenericSetup.exe
GET
200
104.16.235.79:80
http://sos.adaware.com/v1/offer/detail/?_id=a24f81dfaa44ddb17c3d3c2892e69873389afa7b
US
html
44.2 Kb
whitelisted
3968
GenericSetup.exe
GET
200
104.16.235.79:80
http://sos.adaware.com/v1/offer/detail/?_id=d18442e0192390f8e608304cf2c65fff595148ea
US
html
190 Kb
whitelisted
3968
GenericSetup.exe
POST
200
104.16.235.79:80
http://sos.adaware.com/v1/bundle/list/?bundleId=UTW005
US
text
12.3 Kb
whitelisted
2980
installer.exe
POST
200
104.18.88.101:80
http://flow.lavasoft.com/v1/event-stat?ProductID=IS&Type=StubStart
US
text
29 b
whitelisted
3968
GenericSetup.exe
POST
200
104.16.235.79:80
http://sos.adaware.com/v1/h2osuite/offers/?bundleId=UTW005
US
html
107 Kb
whitelisted
2980
installer.exe
POST
200
104.18.88.101:80
http://flow.lavasoft.com/v1/event-stat?ProductID=IS&Type=StubBundleStart
US
text
29 b
whitelisted
3968
GenericSetup.exe
GET
200
104.16.235.79:80
http://sos.adaware.com/v1/offer/detail/?_id=a9d9f2742294d9182dfc52e47c807c0f25e63db6
US
html
32.4 Kb
whitelisted
3968
GenericSetup.exe
GET
200
104.16.235.79:80
http://sos.adaware.com/v1/offer/detail/?_id=27bca1addad3b221066d15c8bf7b5715272ca489
US
html
121 Kb
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3668
chrome.exe
67.215.238.66:443
download-new.utorrent.com
QuadraNet, Inc
US
suspicious
3668
chrome.exe
172.217.22.77:443
accounts.google.com
Google Inc.
US
whitelisted
3668
chrome.exe
216.58.207.46:443
sb-ssl.google.com
Google Inc.
US
whitelisted
3668
chrome.exe
172.217.18.3:443
clientservices.googleapis.com
Google Inc.
US
whitelisted
3668
chrome.exe
216.58.207.68:443
www.google.com
Google Inc.
US
whitelisted
3668
chrome.exe
172.217.18.163:443
ssl.gstatic.com
Google Inc.
US
whitelisted
3968
GenericSetup.exe
104.16.235.79:80
sos.adaware.com
Cloudflare Inc
US
shared
2980
installer.exe
104.18.88.101:80
flow.lavasoft.com
Cloudflare Inc
US
shared
3968
GenericSetup.exe
104.18.87.101:443
flow.lavasoft.com
Cloudflare Inc
US
shared

DNS requests

Domain
IP
Reputation
clientservices.googleapis.com
  • 172.217.18.3
whitelisted
download-new.utorrent.com
  • 67.215.238.66
whitelisted
accounts.google.com
  • 172.217.22.77
shared
www.google.com
  • 216.58.207.68
malicious
ssl.gstatic.com
  • 172.217.18.163
whitelisted
sb-ssl.google.com
  • 216.58.207.46
whitelisted
sos.adaware.com
  • 104.16.235.79
  • 104.16.236.79
whitelisted
flow.lavasoft.com
  • 104.18.88.101
  • 104.18.87.101
whitelisted

Threats

PID
Process
Class
Message
2980
installer.exe
A Network Trojan was detected
ET MALWARE Lavasoft PUA/Adware Client Install
Process
Message
GenericSetup.exe
GenericSetup.exe
GenericSetup.exe
at sciter:init-script.tis
GenericSetup.exe
at sciter:init-script.tis